Browse all
Known Exploited Vulnerabilities (CISA KEV) — all
The full CISA KEV catalog of vulnerabilities confirmed exploited in the wild — filter and search by year, ransomware use, and date added.
1,657 results
| Urgency | CVE | Name / product | Vendor | KEV added |
|---|---|---|---|---|
| High | CVE-2024-7971 ↗ | Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability | Aug 26, 2024 | |
| High | CVE-2024-39717 ↗ | Versa Director — Versa Director Dangerous File Type Upload Vulnerability | Versa | Aug 23, 2024 |
| High | CVE-2021-33044 ↗ | Dahua IP Camera Firmware — Dahua IP Camera Authentication Bypass Vulnerability | Dahua | Aug 21, 2024 |
| High | CVE-2021-33045 ↗ | Dahua IP Camera Firmware — Dahua IP Camera Authentication Bypass Vulnerability | Dahua | Aug 21, 2024 |
| High | CVE-2022-0185 ↗ | Linux Kernel — Linux Kernel Heap-Based Buffer Overflow Vulnerability | Linux | Aug 21, 2024 |
| High | CVE-2021-31196 ↗ | Microsoft Exchange Server — Microsoft Exchange Server Information Disclosure V... | Microsoft | Aug 21, 2024 |
| Critical | CVE-2024-23897 ↗ | Jenkins Jenkins Command Line Interface (CLI) — Jenkins Command Line Interface... | Jenkins | Aug 19, 2024 |
| High | CVE-2024-28986 ↗ | SolarWinds Web Help Desk — SolarWinds Web Help Desk Deserialization of Untrust... | SolarWinds | Aug 15, 2024 |
| High | CVE-2024-38189 ↗ | Microsoft Project — Microsoft Project Remote Code Execution Vulnerability | Microsoft | Aug 13, 2024 |
| High | CVE-2024-38178 ↗ | Microsoft Windows — Microsoft Windows Scripting Engine Memory Corruption Vulne... | Microsoft | Aug 13, 2024 |
| High | CVE-2024-38213 ↗ | Microsoft Windows — Microsoft Windows SmartScreen Security Feature Bypass Vuln... | Microsoft | Aug 13, 2024 |
| High | CVE-2024-38193 ↗ | Microsoft Windows — Microsoft Windows Ancillary Function Driver for WinSock Pr... | Microsoft | Aug 13, 2024 |
| High | CVE-2024-38106 ↗ | Microsoft Windows — Microsoft Windows Kernel Privilege Escalation Vulnerabilit... | Microsoft | Aug 13, 2024 |
| High | CVE-2024-38107 ↗ | Microsoft Windows — Microsoft Windows Power Dependency Coordinator Privilege E... | Microsoft | Aug 13, 2024 |
| High | CVE-2024-36971 ↗ | Android Kernel — Android Kernel Remote Code Execution Vulnerability | Android | Aug 7, 2024 |
| High | CVE-2024-32113 ↗ | Apache OFBiz — Apache OFBiz Path Traversal Vulnerability | Apache | Aug 7, 2024 |
| High | CVE-2018-0824 ↗ | Microsoft Windows — Microsoft COM for Windows Deserialization of Untrusted Dat... | Microsoft | Aug 5, 2024 |
| Critical | CVE-2024-37085 ↗ | VMware ESXi — VMware ESXi Authentication Bypass Vulnerability | VMware | Jul 30, 2024 |
| High | CVE-2024-4879 ↗ | ServiceNow Utah, Vancouver, and Washington DC Now Platform — ServiceNow Improp... | ServiceNow | Jul 29, 2024 |
| High | CVE-2024-5217 ↗ | ServiceNow Utah, Vancouver, and Washington DC Now Platform — ServiceNow Incomp... | ServiceNow | Jul 29, 2024 |
| High | CVE-2023-45249 ↗ | Acronis Cyber Infrastructure (ACI) — Acronis Cyber Infrastructure (ACI) Insecu... | Acronis | Jul 29, 2024 |
| High | CVE-2012-4792 ↗ | Microsoft Internet Explorer — Microsoft Internet Explorer Use-After-Free Vulne... | Microsoft | Jul 23, 2024 |
| High | CVE-2024-39891 ↗ | Twilio Authy — Twilio Authy Information Disclosure Vulnerability | Twilio | Jul 23, 2024 |
| High | CVE-2024-34102 ↗ | Adobe Commerce and Magento Open Source — Adobe Commerce and Magento Open Sourc... | Adobe | Jul 17, 2024 |
| High | CVE-2024-28995 ↗ | SolarWinds Serv-U — SolarWinds Serv-U Path Traversal Vulnerability | SolarWinds | Jul 17, 2024 |
| High | CVE-2022-22948 ↗ | VMware vCenter Server — VMware vCenter Server Incorrect Default File Permissio... | VMware | Jul 17, 2024 |
| High | CVE-2024-36401 ↗ | OSGeo GeoServer — OSGeo GeoServer GeoTools Eval Injection Vulnerability | OSGeo | Jul 15, 2024 |
| High | CVE-2024-38112 ↗ | Microsoft Windows — Microsoft Windows MSHTML Platform Spoofing Vulnerability | Microsoft | Jul 9, 2024 |
| High | CVE-2024-38080 ↗ | Microsoft Windows — Microsoft Windows Hyper-V Privilege Escalation Vulnerabili... | Microsoft | Jul 9, 2024 |
| High | CVE-2024-23692 ↗ | Rejetto HTTP File Server — Rejetto HTTP File Server Improper Neutralization of... | Rejetto | Jul 9, 2024 |
| High | CVE-2024-20399 ↗ | Cisco NX-OS — Cisco NX-OS Command Injection Vulnerability | Cisco | Jul 2, 2024 |
| High | CVE-2022-24816 ↗ | OSGeo JAI-EXT — OSGeo GeoServer JAI-EXT Code Injection Vulnerability | OSGeo | Jun 26, 2024 |
| High | CVE-2022-2586 ↗ | Linux Kernel — Linux Kernel Use-After-Free Vulnerability | Linux | Jun 26, 2024 |
| High | CVE-2020-13965 ↗ | Roundcube Webmail — Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | Roundcube | Jun 26, 2024 |
| High | CVE-2024-32896 ↗ | Android Pixel — Android Pixel Privilege Escalation Vulnerability | Android | Jun 13, 2024 |
| Critical | CVE-2024-26169 ↗ | Microsoft Windows — Microsoft Windows Error Reporting Service Improper Privile... | Microsoft | Jun 13, 2024 |
| High | CVE-2024-4358 ↗ | Progress Telerik Report Server — Progress Telerik Report Server Authentication... | Progress | Jun 13, 2024 |
| High | CVE-2024-4610 ↗ | Arm Mali GPU Kernel Driver — Arm Mali GPU Kernel Driver Use-After-Free Vulnera... | Arm | Jun 12, 2024 |
| Critical | CVE-2024-4577 ↗ | PHP Group PHP — PHP-CGI OS Command Injection Vulnerability | PHP Group | Jun 12, 2024 |
| High | CVE-2017-3506 ↗ | Oracle WebLogic Server — Oracle WebLogic Server OS Command Injection Vulnerabi... | Oracle | Jun 3, 2024 |
| Critical | CVE-2024-24919 ↗ | Check Point Quantum Security Gateways — Check Point Quantum Security Gateways... | Check Point | May 30, 2024 |
| Critical | CVE-2024-1086 ↗ | Linux Kernel — Linux Kernel Use-After-Free Vulnerability | Linux | May 30, 2024 |
| High | CVE-2024-4978 ↗ | Justice AV Solutions Viewer — Justice AV Solutions (JAVS) Viewer Installer Emb... | Justice AV Solutions | May 29, 2024 |
| High | CVE-2024-5274 ↗ | Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability | May 28, 2024 | |
| High | CVE-2020-17519 ↗ | Apache Flink — Apache Flink Improper Access Control Vulnerability | Apache | May 23, 2024 |
| Critical | CVE-2023-43208 ↗ | NextGen Healthcare Mirth Connect — NextGen Healthcare Mirth Connect Deserializ... | NextGen Healthcare | May 20, 2024 |
| High | CVE-2024-4947 ↗ | Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability | May 20, 2024 | |
| High | CVE-2014-100005 ↗ | D-Link DIR-600 Router — D-Link DIR-600 Router Cross-Site Request Forgery (CSRF... | D-Link | May 16, 2024 |
| High | CVE-2021-40655 ↗ | D-Link DIR-605 Router — D-Link DIR-605 Router Information Disclosure Vulnerabi... | D-Link | May 16, 2024 |
| High | CVE-2024-4761 ↗ | Google Chromium V8 — Google Chromium V8 Out-of-Bounds Memory Write Vulnerabili... | May 16, 2024 |
Source: official U.S. government open data. This is an organized index, not an official U.S. government site. "Explained" links to our summary page; otherwise links go to the official primary source.